Certain Authorized Events Not Being Reported In The Top Secret TSSUTIL Report
search cancel

Certain Authorized Events Not Being Reported In The Top Secret TSSUTIL Report

book

Article ID: 139331

calendar_today

Updated On:

Products

Top Secret

Issue/Introduction

TSSUTIL REPORT EVENT(ALL) RESOURCE(IBMFAC,'FPZ.ACCELERATOR.COMPRESSION') DATE(-10) LONG END

not showing authorized access events.

Only security violations are reported.

Environment

Release :

Component : CA Top Secret for z/OS

Resolution

.Authorized access is logged when:

1. The user has the AUDIT attribute.
2. There is a ACTION(AUDIT) on the PERMIT for that resource.
3. The resource is on the AUDIT record
4. Or if the resource was accessed through a bypass attribute.

Otherwise only violations get logged.